The ClickFix campaign has introduced a novel method for delivering malware through fake CAPTCHA prompts on compromised websites. Users are tricked into executing commands that lead to malware infections, making this a significant threat in web security.
How the ClickFix Campaign Operates
This malicious campaign begins when a user visits an altered website. The site presents a deceptive CAPTCHA or repair prompt, instructing users to open the Windows Run dialog, paste a specific command, and execute it. Unlike legitimate CAPTCHA checks, this method requires users to run system commands, which is unusual and risky.
Microsoft Threat Intelligence has shed light on how these attacks are executed. The attackers cleverly store a malicious script disguised as a PNG file within the browser cache. This script is downloaded beforehand, minimizing the need for obvious downloads and allowing attackers to execute commands more covertly.
Technical Aspects and Risks
The attack leverages Windows Script Host to execute a VBScript, which is stored in the browser cache. This VBScript retrieves additional malicious scripts, such as a PowerShell script, furthering the attack’s reach. The design targets credential theft, as attackers aim to harvest sensitive information from the victim’s device.
Compromised websites involved in these attacks do not follow standard malware patterns, as they prefetch the harmful script into the cache rather than downloading it during execution. This technique aids in evading detection by conventional security measures that focus on new downloads.
Preventive Measures and Detection
Security experts suggest several measures to combat these threats. Microsoft recommends enabling cloud-delivered and web protection, along with thorough monitoring of browser-cache activities and unusual child processes. Investigating alerts for command execution and outbound connections can be crucial in detecting these attacks.
Users are advised to be cautious of any webpage requesting them to paste commands into system dialogs like Run, Terminal, or PowerShell. Recognizing this boundary can prevent the execution of harmful commands, even when the payload is preloaded.
Conclusion and Future Outlook
The ClickFix campaign highlights a growing trend in human-led infection strategies that exploit user trust in security processes. While Microsoft has not disclosed the full scope of affected individuals, the campaign underlines the importance of vigilance and robust security practices to mitigate such threats. Continued research and updates from security teams will be vital in countering this evolving threat landscape.
